Live data from Hacker News

TrueCrypt suggesting migration to BitLocker?

truecrypt.sourceforge.net

191–200 of 414 posts

Re: TrueCrypt suggesting migration to BitLocker?

#191

In order of likelihood: * Defaced site, timed to screw up a big announcement * Rogue content maintainer * Phase II of audit turned up something rather bad (edit: NO - see tptacek below) edit: Variations on "developer forced to do this" (cf simmerian's comment): * Developer was big brother all along and they are shutting it down * Security vuln about to be disclosed, dev scrambles to inform (albeit poorly) * Legally o…

What if this is an attempt to smoke out the TrueCrypt devs?

While this move seems odd, the new binaries are properly signed and the domains have been updated accordingly. If this was another project, like Rails, the maintainer could come out and say they were hacked and the last good version was X. Otherwise, the project would likely die off.

But since we know so little about the TrueCrypt maintainers, there's little way for us to hear that this isn't legitimate. In order to keep the project from dying (if this is a hoax), they would have to prove that they are the maintainers, because any plausible deniability would undermine their claim that the change was not legitimate.

Re: TrueCrypt suggesting migration to BitLocker?

#192

Sourceforge seems to have recently updated their password hashing algorithm, so that might hint at the cause of a compromise. Here's the body of the email sent to me on the 22nd: Greetings, To make sure we're following current best practices for security, we've made some changes to how we're storing user passwords. As a result, the next time you go to login to your SourceForge.net account, you will be prompted to cha…

Sourceforge's representative says it's unrelated: https://news.ycombinator.com/item?id=7813121

Re: TrueCrypt suggesting migration to BitLocker?

#193

Earlier quoted context omitted.

It could be that they've simply lost interest in developing it. It's quite the ongoing responsibility, and they may well be tired of working on it - a decade is a long time in anyone's life. If this is true, then perhaps such listlessness was also catalysed by the ongoing audit. Maybe seeing such a mass of crowdfunding income towards a project to pick Truecrypt apart, in contrast to the scant donations to its develop…

If you're developing a free product and you're going to throw in the towel anyway, why not just open up the sources with a liberal license and/or hand the project over to someone else who's willing to carry the torch.

It may be the same strong sense of ownership and control that precluded the liberalisation of Truecrypt's license during its lifetime in the past decade.

Re: TrueCrypt suggesting migration to BitLocker?

#194
State sponsored hacking?

I'd think it's to organised for a defacement (re-written code, signed binaries, two sites compromised). I can't see money being made, so can't see criminal.

That kinda leaves a state sponsor with the organisation skills and commitment. It gets to create doubt about the product and slow it's uptake down.

Or it's real :/

Re: TrueCrypt suggesting migration to BitLocker?

#195

Earlier quoted context omitted.

It could be that they've simply lost interest in developing it. It's quite the ongoing responsibility, and they may well be tired of working on it - a decade is a long time in anyone's life. If this is true, then perhaps such listlessness was also catalysed by the ongoing audit. Maybe seeing such a mass of crowdfunding income towards a project to pick Truecrypt apart, in contrast to the scant donations to its develop…

If you're developing a free product and you're going to throw in the towel anyway, why not just open up the sources with a liberal license and/or hand the project over to someone else who's willing to carry the torch.

It's already open-source.

Re: TrueCrypt suggesting migration to BitLocker?

#196
post #144

Interestingly enough, they also changed the TrueCrypt license. -TrueCrypt License Version 3.0 +TrueCrypt License Version 3.1 This lead me to think about the legal implications of changing a software license using stolen signing keys, when signing keys are all that you have to verify that the software is official (such is the case with TrueCrypt and its anonymous authors). If the license is changed, and the package is…

If, and only if, this is a legitament change done by a majority copyright holder(s) and/or project owner.

Re: TrueCrypt suggesting migration to BitLocker?

#197
post #191

In order of likelihood: * Defaced site, timed to screw up a big announcement * Rogue content maintainer * Phase II of audit turned up something rather bad (edit: NO - see tptacek below) edit: Variations on "developer forced to do this" (cf simmerian's comment): * Developer was big brother all along and they are shutting it down * Security vuln about to be disclosed, dev scrambles to inform (albeit poorly) * Legally o…

What if this is an attempt to smoke out the TrueCrypt devs? While this move seems odd, the new binaries are properly signed and the domains have been updated accordingly. If this was another project, like Rails, the maintainer could come out and say they were hacked and the last good version was X. Otherwise, the project would likely die off. But since we know so little about the TrueCrypt maintainers, there's little…

[deleted]

Re: TrueCrypt suggesting migration to BitLocker?

#199

In order of likelihood: * Defaced site, timed to screw up a big announcement * Rogue content maintainer * Phase II of audit turned up something rather bad (edit: NO - see tptacek below) edit: Variations on "developer forced to do this" (cf simmerian's comment): * Developer was big brother all along and they are shutting it down * Security vuln about to be disclosed, dev scrambles to inform (albeit poorly) * Legally o…

After examining all the facts, I think it's most likely they just didn't want to develop it anymore:

    * PGP matches
    * Authenticode matches
    * SourceForge data was modified
    * DNS records were modified
And to top it off, let's put ourselves in the theoretical attacker's shoes, the binaries when run make no unexpected connection attempts or write to any unexpected places and don't appear to contain any unexpected imports, so if this was a hack, it's a very stealthy and very boring one. The most they achieved would be uninteresting to most attackers. It would only really be an effective attack against people who had TrueCrypt volumes but not a current copy of TrueCrypt as there's no compelling reason for anyone to upgrade to 7.2 and certainly they'd be skeptical after this. Any attacker with the intelligence and patience for such an attack would surely realize how poor an execution this would be. A better attack would be "here, it's TrueCrypt 8, it has loads of EFI support and mad security, everyone should install it, it's the best!". There's simply no reason to shut it down like this, unless the attack is just an elaborate practical joke.

It's quite possible this came from 1 big developer hack, but considering how the release was done, with full source and everything for every supported platform... if it was a hack, it's a very, very good one. They've also decided to modify the license terms, perhaps bringing it into compatibility with more common FOSS licenses.

I think it's far more likely at this point that the devs, who had not updated their software in years, finally decided to call the project over and have marked it insecure because the codebase is now unmaintained and should be assumed insecure.

Re: TrueCrypt suggesting migration to BitLocker?

#200
Seems like a state-financed targeted attack. It only has to last long enough to get the target (a user of truecrypt) to switch off it. My guess is whoever they are going after is being inundated with links to the page. They must also be a Windows user, since they took great pains to demo how to move the data.
Post reply on HN